What should I do after an account or email compromise?

Updated Corrections

October 2, 20262 min read

Use your account provider’s official recovery flow first. After you regain access, set a unique password, enable multi-factor authentication, and check sessions, forwarding rules and recovery contacts. Start with your email inbox if it controls password resets for other accounts.

Sources

Regain control of the account

  1. Open the provider’s official website or app yourself. If you cannot sign in, use its account-recovery process. Do not use a recovery link sent by an unfamiliar person.
  2. On a device you trust, choose a new password that you have not used elsewhere. Change reused passwords on other important accounts.
  3. Enable multi-factor authentication. Review the recovery email address and phone number, and remove changes you did not make.
  4. Review active sessions and recent logins. Sign out sessions you do not recognize. For email, check forwarding addresses, filters and connected apps.
  5. Tell contacts to disregard suspicious messages sent while the account was compromised. Keep relevant messages and screenshots as evidence.

Follow the FTC’s account-recovery steps and two-factor authentication guidance.

Choose the right help

Problem Where to start
You cannot sign in The account provider’s official recovery process
An unfamiliar bank or card transaction The bank’s app or the number on your card
Someone opened accounts in your name IdentityTheft.gov
Someone posted your personal data The hosting platform’s abuse channel and our doxxing response guide

Do not share passwords, one-time codes or recovery phrases with someone who contacts you unexpectedly. Do not give an unsolicited recovery service remote access to your device.

What a credit freeze can and cannot do

A free credit freeze helps restrict new credit applications. It does not restore a hacked login or stop transactions on existing bank accounts. Contact the bank about existing-account fraud. A password-only takeover calls for account recovery first.

How this differs from a breach notice or public listing

A company breach notice describes data an organization held; it does not necessarily mean someone controls your account. See how to check a breach notice. An email address appearing publicly does not, by itself, prove a password was stolen.

After urgent recovery steps, you can check public people-search listings separately. A free Delist scan reports exposure on the sources we check. Paid removal work requires separate authorization. Delist does not restore hacked accounts, investigate attackers or erase breach dumps.

More guides

Find out what data brokers know about you

A free scan shows which sites are exposing your name, phone, address and email, and Delist files the removals for you.

Start your free scan No card required